Explore malware, protestware, install-hook abuse, staged payload carriers, crypto mining, and typosquatting. These reports have OSV or public advisory evidence. Each report identifies the package version, supporting evidence, advisory sources, and current Firewall decision.
Updated 10 Oct 2026, 20:21 UTC. Ordered by latest scan.
This is unconsented install-time command execution and host-data exfiltration to a third-party endpoint. The import-time trigger reinforces the malicious lifecycle behavior.
An automatic preinstall hook launches a deliberately obscured payload with concrete credential and outbound automation capabilities. This is malicious install-hook abuse.
This is a concrete malicious install-time chain: an automatic lifecycle hook executes an opaque payload with credential, network, filesystem, and process capabilities unrelated to the sta...
The automatic preinstall hook executes a deliberately concealed, capability-rich payload. This is concrete install-hook abuse, not package-aligned setup.